The information blocking rule reshaped how practices and health IT vendors must handle electronic health information. At its core, it discourages practices that unnecessarily interfere with the access, exchange, or use of electronic health information. Here is a plain-language overview of what it means and how to stay on the right side of it.
What information blocking is
Established under the 21st Century Cures Act and implemented by ONC (now part of the Assistant Secretary for Technology Policy), the rule defines information blocking as a practice by a healthcare provider, health IT developer, or network that is likely to interfere with access, exchange, or use of electronic health information (EHI), except as required by law or covered by an exception.
The shift toward access
In practice, this means patients and their authorized apps, as well as other providers, are entitled to timely electronic access to health information. Foot-dragging, unnecessary delays, or arbitrary barriers to releasing records can constitute information blocking. The default posture has shifted from "share if asked nicely" to "share unless there is a valid reason not to."
The exceptions, in brief
- Preventing harm to a patient or another person
- Privacy protection consistent with the law
- Security measures that are reasonable and necessary
- Infeasibility where fulfilling a request is genuinely not practicable
- Health IT performance (e.g., maintenance), and others defined in the rule
What practices should do
- Make timely electronic access the default, typically through your patient portal and APIs
- Document the basis when you decline a request, mapped to a recognized exception
- Train staff so requests are not delayed by uncertainty or habit
- Confirm your certified EMR supports the required standardized API access
Why it matters
Beyond compliance, the rule reflects a broader expectation that patients control and can move their own health data. Practices that build smooth electronic access reduce administrative burden (fewer manual record requests) while meeting both the letter and the spirit of the rule. Because enforcement details and disincentives continue to develop, consult the official ONC and HHS resources for current specifics.
Where practices commonly stumble
Most information-blocking problems are not deliberate; they are habits left over from a slower era. A policy of releasing results only after a clinician reviews them, a routine multi-day delay on record requests, or staff who default to "we'll mail it" rather than enabling portal access can all run afoul of the rule even without any intent to obstruct. The practical fix is to examine your current release practices and ask, for each delay or barrier, whether a legitimate exception justifies it. If not, make electronic access the default.
Information blocking versus HIPAA
It helps to keep two regimes distinct. HIPAA's right of access governs a patient's ability to obtain their records and sets limits on how you respond. The information-blocking rule is broader, targeting practices that interfere with access, exchange, or use of electronic health information among patients, providers, and others. They overlap but are not identical, and a practice can satisfy one while running afoul of the other. When in doubt, lean toward enabling access through your certified systems, document any refusal against a recognized exception, and check the current official guidance, since this area continues to evolve.